HTTP or HTTPS: what changes for visitors, forms and the services that call your site

Short answer: use HTTPS, always. Here every domain gets a free SSL certificate automatically, so the real question is almost never “do I have to buy one?” but “is my site actually using it?” Because http:// and https:// are two different addresses, and a site can answer on both at once.

What changes, point by point

HTTP HTTPS
What travels Everything in the clear: the page, what you type into a form, passwords, the session cookie. Everything encrypted. Whoever is on the path cannot read the content, though they can still see which domain you connect to.
Tampering on the way The content can be changed on the way without anyone noticing. Any change is detected and the connection is refused.
What the browser shows A “not secure” warning, especially on pages with forms. The padlock.
Services that call your site Many refuse the address. Webhooks and payment notifications usually require HTTPS. Accepted. It is the normal requirement.
Search At a disadvantage. Google treats HTTPS as a ranking signal in your favour.

The fourth row deserves a note. For services that call your site, the practical rule is simple: if the callback address is http://, many will not even try. One example is the WhatsApp Cloud API webhooks, which according to Meta’s documentation require an HTTPS address: Meta webhooks. And the padlock only appears if everything the page loads also comes over HTTPS: a single image at an http:// address is enough to spoil it.

How to tell whether your site is really on HTTPS

1 Confirm the certificate exists. In cPanel, open SSL/TLS Status: it lists each domain’s certificate and the date it renews. If a new domain does not have one yet, it can take from a few minutes to an hour.
2 Type the address with http:// in the browser. It should move to https:// by itself. If it stays on HTTP, the redirect is missing.
3 Look at the code the server returns. In a terminal, curl -I http://yourcompany.com should show a 301 and a location line with the https:// address. More on reading this in 301 or 302.
4 Add the redirect if it is missing: redirecting HTTP to HTTPS with .htaccess.
5 On WordPress, set both addresses (the WordPress one and the site one, under Settings › General) to the https version, and fix whatever stayed mixed: changing the site address and mixed content.
Do not force HTTPS before the certificate is valid. If you do, the browser shows an insecure-connection warning instead of your site. And if the padlock does not appear once everything is right, follow the causes, in order.
Once everything has been stable for a while, you can go further and tell browsers to always use HTTPS (HSTS). It is a hard decision to undo, though: read HSTS explained first.

The padlock is missing or the site still opens on HTTP? Tell us the address and what you see.

Open a support ticket

SEE ALSO

What is an SSL certificate and why does it matter?

How to redirect HTTP to HTTPS with .htaccess

No padlock on your site: the causes, in order

SSL certificates

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from R118.80/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?